GAO Site Hackers Were Protesting Afghan War

Government officials say they've discovered the security flaw exploited by the vandals, but expressed little hope of catching the perpetrators

0shares

Hackers who defaced the Web site of the U.S. General Accounting Office earlier this week say they acted to protest the U.S. war in Afghanistan as well as the plight of Palestinians and Kashmiris. Meanwhile, government officials say they've discovered the security flaw exploited by the vandals, but expressed little hope of catching the perpetrators.

A group claiming to be part of a large hacker organization known as the Alqaeda Muslim Alliance compromised a server belonging to the U.S. General Accounting Office in Washington on Monday.

The Anti India Crew apparently breached the security of at least one mail server, an FTP server and two Web servers, according to data on the Alldas.de defacement archive.

"What got us all together were the recent attacks on Afghanistan, the fake and totally made up propaganda of Indian media against the Muslim nation," said someone claiming to be one of the attackers in an unsigned response to an e-mail from an address posted on the defaced site. "They can bomb and destroy a whole country or a whole nation which is actually killing people who can't even afford to buy new clothes for themselves and we can't even protest? We cant even ask for peace? We can't even modify htmls [sic] in this cyberworld? It won't harm humans , it won't be as bad as killing the innocent. It shouldn't be considered as a terrorism act."

Instead of the normal GAO information, users going to listserv.gao.gov saw a message, instead, left by the hackers. In it, the AIC admonishes other hackers for using the Alqaeda Muslim Alliance name and warns that there will be more attacks against Indian, Israeli and U.S. Web sites.

"We warned already we will hit us/in/il government servers until [sic] there is peace around us! Long live Kashmir and Palestine," part of the defacement read.

Indeed, the Alldas site, which archives defaced Web pages, lists dozens of sites, many of them with Indian or Israeli domain names, which the AIC has defaced.

//Related Articles

While GAO officials said they are "99.9 percent" sure about how the attackers got into the system, they are less enthusiastic about the prospsects of tracking the crew down. "We're working with the FBI, but they need more information. We're sharing all of our information with them and there are a few other things to track down, but it's a neverending story. [The hackers] are pretty smart," said Tony Cicco, chief information officer of the GAO in Washington.
Cicco said his staff is currently rebuilding the listserv logs, which AIC deleted during its break-in. That work could take until Tuesday. As close as Cicco can tell at this point, the attack occurred at about 3:45 a.m. Monday.

The GAO is the federal government's investigative arm and is responsible for keeping tabs on Congress as well as other government agencies.

AIC claims to be one member of the hacking triumvirate calling itself the Alqaeda Muslim Alliance. The other members are Gforce Pakistan and Pakistan Hackerz Club.

Automatic Renewal Program: Your subscription will continue without interruption for as long as you wish, unless
you instruct us otherwise. Your subscription will automatically renew at the end of the term unless you authorize
cancellation. Each year, you'll receive a notice and you authorize that your credit/debit card will be charged the
annual subscription rate(s). You may cancel at any time during your subscription and receive a full refund on all
unsent issues. If your credit/debit card or other billing method can not be charged, we will bill you directly instead. Contact Customer Service